CVE-2010-4243
Last modified
CVE-2010-4243 is a vulnerability of currently unknown severity. fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.. EPSS estimates a 0.91% chance of exploitation in the next 30 days.
Description
fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | < 2.6.37 |
References
- http://grsecurity.net/~spender/64bit_dos.cBroken Link
- http://lkml.org/lkml/2010/8/27/429Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/29/206Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/138Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/378Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/15Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/6Mailing List, Third Party Advisory
- http://secunia.com/advisories/42884Third Party Advisory
- http://secunia.com/advisories/46397Third Party Advisory
- http://www.exploit-db.com/exploits/15619Exploit, Third Party Advisory, VDB Entry
- http://www.redhat.com/support/errata/RHSA-2011-0017.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45004Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=625688Issue Tracking, Third Party Advisory
- http://grsecurity.net/~spender/64bit_dos.cBroken Link
- http://lkml.org/lkml/2010/8/27/429Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/29/206Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/138Mailing List, Patch, Third Party Advisory
- http://lkml.org/lkml/2010/8/30/378Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/15Mailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/11/22/6Mailing List, Third Party Advisory
- http://secunia.com/advisories/42884Third Party Advisory
- http://secunia.com/advisories/46397Third Party Advisory
- http://www.exploit-db.com/exploits/15619Exploit, Third Party Advisory, VDB Entry
- http://www.redhat.com/support/errata/RHSA-2011-0017.htmlThird Party Advisory
- http://www.securityfocus.com/archive/1/520102/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45004Third Party Advisory, VDB Entry
- http://www.vmware.com/security/advisories/VMSA-2011-0012.htmlThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=625688Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4243?
How severe is CVE-2010-4243?
How do I fix CVE-2010-4243?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-4237Mercurial before 1.6.4 fails to verify the Common Name field…5.9
- CVE-2010-4238The vbd_create function in Xen 3.1.2, when the Linux kernel …
- CVE-2010-4239Tiki Wiki CMS Groupware 5.2 has Local File Inclusion9.8
- CVE-2010-4240Tiki Wiki CMS Groupware 5.2 has XSS6.1
- CVE-2010-4241Tiki Wiki CMS Groupware 5.2 has CSRF8.8
- CVE-2010-4242The hci_uart_tty_open function in the HCI UART driver (drive…
- CVE-2010-4244Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2010-4245pootle 2.0.5 has XSS via 'match_names' parameter6.1
- CVE-2010-4246Multiple cross-site scripting (XSS) vulnerabilities in graph…
- CVE-2010-4247The do_block_io_op function in (1) drivers/xen/blkback/blkba…
- CVE-2010-4248Race condition in the __exit_signal function in kernel/exit.…
- CVE-2010-4249The wait_for_unix_gc function in net/unix/garbage.c in the L…
Are you affected by CVE-2010-4243?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
